Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-23222

74
FAUCET Score

CVE-2024-23222 is a critical type confusion vulnerability impacting multiple Apple products, including iOS, iPadOS, macOS, Safari, tvOS, and visionOS. This high-severity flaw (CVSS 8.8) allows arbitrary code execution when processing maliciously crafted web content, requiring user interaction but having low attack complexity. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog and association with the "Coruna" exploit. Apple has released patches across various operating system versions, including backports for older devices, to address this significant threat. While no public exploit code is widely available, the active exploitation and extensive media coverage highlight its critical nature.

Impacted Technologies

VendorProductVersion(s)CPE
< 17.3CPE matchmatch criteria
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
< 15.8.7CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
>= 16.0, < 16.7.5CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
>= 17.0, < 17.3CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
< 15.8.7CPE matchmatch criteria
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
10.59%
Probability of exploitation in next 30 days
EPSS Percentile
95.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jan 23, 2024
This CVE's current EPSS score of 0.1059 is in the 95th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: webkitgtk4-0:2.48.3-2.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: webkit2gtk3-0:2.38.5-1.el8_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: webkit2gtk3-0:2.46.3-1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: webkit2gtk3-0:2.46.3-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: webkit2gtk3-0:2.46.3-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: webkit2gtk3-0:2.46.3-1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: webkit2gtk3-0:2.46.3-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: webkit2gtk3-0:2.46.3-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: webkit2gtk3-0:2.46.3-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: webkit2gtk3-0:2.38.5-1.el9_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: webkit2gtk3-0:2.46.1-1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: webkit2gtk3-0:2.46.3-1.el9_2
View patch
applevendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: webkitgtk3

Vendor Advisories (2)

redhatCVE-2024-23222Important

webkitgtk: type confusion may lead to arbitrary code execution

Jan 23, 2024
appleapple:126632

About the security content of iOS 15.8.7 and iPadOS 15.8.7 - Apple Support

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
seclists.org / fulldisclosure/2024/Feb/6
Third Party Advisory
seclists.org / fulldisclosure/2024/Jan/34
Third Party Advisory
seclists.org / fulldisclosure/2024/Jan/40
Third Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/US43EQFC2IS66EA2CPAZFH2RQ6WD7PKF
Broken Link
support.apple.com / en-us/HT214055
Release NotesVendor Advisory
support.apple.com / en-us/HT214059
Release NotesVendor Advisory
support.apple.com / en-us/HT214061
Release NotesVendor Advisory
support.apple.com / kb/HT214055
Release NotesVendor Advisory
support.apple.com / kb/HT214056
Release NotesVendor Advisory
support.apple.com / kb/HT214057
Release NotesVendor Advisory
support.apple.com / kb/HT214058
Release NotesVendor Advisory
support.apple.com / kb/HT214059
Release NotesVendor Advisory
support.apple.com / kb/HT214061
Release NotesVendor Advisory
support.apple.com / kb/HT214063
Release NotesVendor Advisory
support.apple.com / kb/HT214070
Release NotesVendor Advisory
support.apple.com / en-us/118479
Release NotesVendor Advisory
support.apple.com / en-us/120304
Release NotesVendor Advisory
support.apple.com / en-us/120305
Release NotesVendor Advisory
support.apple.com / en-us/120307
Release NotesVendor Advisory
support.apple.com / en-us/120309
Release NotesVendor Advisory
support.apple.com / en-us/120310
Release NotesVendor Advisory
support.apple.com / en-us/120311
Release NotesVendor Advisory
support.apple.com / en-us/120339
Release NotesVendor Advisory
support.apple.com / en-us/126632
Release NotesVendor Advisory